OnlyState
Social consensus, distilled to a single integer
A protocol-layer cryptographic primitive that compresses infinite social graphs, group memberships, and decentralised economies into a single, constant-size on-chain mathematical state using Zero-Knowledge Prime Integer Relations (ZK-PIR) and the Prouhet-Tarry-Escott problem. 100,000 members represented as one 16-element array — no databases, no identity arrays, no state bloat.
Overview
OnlyState is a protocol-layer cryptographic primitive that compresses social graphs, group memberships, and decentralised economies into a single constant-size on-chain state. It uses Zero-Knowledge Prime Integer Relations (ZK-PIR) and the Prouhet-Tarry-Escott (PTE) problem to prove membership without storing a single wallet address.
No databases. No identity arrays. No state bloat. Just pure Proof-of-Coherence.
Architecture
Client Layer (Browser / WASM)
Users enter a private vector. snarkjs runs the ZK circuit locally, generating a Groth16 proof (pA, pB, pC) — 300–500 bytes — and submits it to chain.
On-Chain Layer (Solidity)
- OnlyState.sol — createGroup(), proveCoherenceAndJoin(), verifyMembership()
- OSTA.sol — ERC-20 token minted exclusively by solving the ZK-PIR circuit
- Verifier.sol — auto-generated by snarkjs, verifies Groth16 proofs on-chain
Off-Chain Coherence Nodes (Rust)
Axum + tokio + redb (persistent KV) + moka (in-memory cache). Nodes index keyword hashes to encrypted IPFS CIDs and serve search results for ZK-gated decryption.
O(1) State Formula
An entire social group of 100,000 members is represented on-chain as exactly one 16-element array — the group's Thue-Morse sequence. The Prouhet-Tarry-Escott power-sum equations verified by the ZK circuit ensure membership without storing a single wallet address.
Key Mathematical Concepts
| Concept | Role |
|---|---|
| Prouhet-Tarry-Escott (PTE) | Membership proof: vector V satisfies equal power sums against the group state |
| Thue-Morse sequence | Public group state — aperiodic binary sequence encoding ±1 signs |
| Groth16 / snarkjs | ZK proving system — generates 300-byte proof from private vector |
| BN254 scalar field | Prime field for all ZK arithmetic — no floats, integers scaled ×10⁶ |
| RSA Accumulator | V2 path: compress member set into a single 2048-bit modular integer |
The OSTA Token
OSTA is minted exclusively by solving the ZK-PIR circuit and submitting a valid Groth16 proof on-chain. No staking. No time-based emissions. Only math.
Utility: search fees → Coherence Nodes, state creation burns, node staking, DAO voting weight, compute bounties for ZK proof outsourcing.
Roadmap
- Demo playground — interactive React UI
- Circom ZK circuit — zk_pir.circom (N=16, C=4)
- Smart contracts — OSTA.sol + OnlyState.sol + Foundry tests
- Rust PIR Core — circuit.rs, proof.rs, verifier.rs
- Rust Coherence Node — axum + redb + moka indexer
- Browser WASM integration — snarkjs prover in demo
- Trusted setup ceremony — real MPC ceremony for mainnet
- Testnet deployment — Arbitrum Sepolia
- Cryptographic audit — ZK circuit audit (Veridise / Zellic)
Key Highlights
- O(1) on-chain state — 100,000 members as one 16-element array
- ZK-PIR circuit proving membership via Prouhet-Tarry-Escott power sums
- OSTA token minted only by solving ZK circuit — no staking, no emissions
- Rust coherence nodes with redb persistence and moka cache